|
221
|
- |
|
-
|
-
|
Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin functions allows attackers to trick authenticated administrators into performing un…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-42286
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222
|
8.8 |
HIGH
Network
|
-
|
-
|
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by …
New
|
CWE-78
OS Command
|
CVE-2026-42215
|
2026-05-9 07:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223
|
- |
|
-
|
-
|
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, the inc "filename" directive in GPPL postprocessor f…
New
|
CWE-22 CWE-200 CWE-295 CWE-918
Path Traversal Information Exposure Improper Certificate Validation Server-Side Request Forgery (SSRF)
|
CVE-2026-42213
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224
|
- |
|
-
|
-
|
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Opening a .gpp file in the SolidCAM Postprocessor ID…
New
|
CWE-400 CWE-611 CWE-776
Uncontrolled Resource Consumption XXE XML Entity Expansion
|
CVE-2026-42212
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225
|
6.5 |
MEDIUM
Network
|
-
|
-
|
FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with retained publish permission can crash the FlashMQ broker when both set_retained_mes…
New
|
CWE-369
Divide By Zero
|
CVE-2026-42209
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
226
|
- |
|
-
|
-
|
Roadiz is a polymorphic content management system based on a node system. Prior to versions 2.3.43, 2.5.45, 2.6.31, and 2.7.18, the roadiz/openid package generates an OIDC nonce in OAuth2LinkGenerato…
New
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-42206
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
227
|
8.8 |
HIGH
Network
|
-
|
-
|
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in the ActionsController of the Avo framework. Due to i…
New
|
CWE-284 CWE-639
Improper Access Control Authorization Bypass Through User-Controlled Key
|
CVE-2026-42205
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
228
|
6.5 |
MEDIUM
Network
|
-
|
-
|
nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-toggle/toggle/{resource}/{resourceId}) was protected only by web + auth:<guard>…
New
|
CWE-285
Improper Authorization
|
CVE-2026-42202
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
229
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand_rows() can corrupt the relationship between the grid’s logical dimensions and …
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-42199
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
230
|
3.4 |
LOW
Network
|
-
|
-
|
draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts a ?gitlab= URL parameter that overrides the GitLab server URL used during OAut…
New
|
CWE-200 CWE-601
Information Exposure Open Redirect
|
CVE-2026-42195
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|